• Title/Summary/Keyword: Security Service Agency

Search Result 173, Processing Time 0.022 seconds

A Study on Countering SIP-based VoIP Spam using VoIP-RBL (VoIP-RBL을 이용한 SIP기반 VoIP스팸 차단 방법)

  • Yoon, Seok-Ung;Jung, Hyun-Cheol;Park, Hae-Ryoung;Won, Yoo-Jae;Yoo, Hyeong-Seon
    • Proceedings of the Korean Information Science Society Conference
    • /
    • 2011.06d
    • /
    • pp.135-136
    • /
    • 2011
  • The more VoIP service is widely used, the more VoIP spam becomes threatened. Both VoIP spam violates the user's privacy and VoIP spam can cause money trouble. Therefore, it is important to reduce the VoIP spam but it is not easy to adopt some useful techniques to counter e-mail spam due to VoIP characteristics. We propose a technique using VoIP-RBL for countering SIP-based VoIP spam.

A Study on the MyData Service Model Based on DID Platform (DID 플랫폼 기반의 마이데이터 서비스 모델 연구)

  • Sohyeon Park;Hyunjun Kim;Kanghyo Lee;Tae Gyun Ha;Kyungbaek Kim
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2023.05a
    • /
    • pp.268-270
    • /
    • 2023
  • 기존 Web2.0 시대의 플랫폼 기업은 서비스를 통해 생성된 개인 데이터로 다양한 비즈니스를 창출해왔다. 하지만 데이터 제공자인 개인은 해당 수익에서 제외되는 모순된 상황에 놓였다. 이에 개인이 자신의 데이터를 적극 관리·통제하면서 능동적으로 활용할 수 있는 개념인 마이데이터(MyData)가 등장했다. 국내에서는 '20.8월 데이터3법(개인정보보호법, 신용정보법, 정보통신망법)이 통과되면서 신용정보법에 근거해 금융 분야 마이데이터 서비스가 활성화되기 시작했다. 그러나 현존하는 마이데이터 플랫폼은 중앙화된 시스템으로 본래 취지와 다르게 개인의 데이터 소유권과 통제권을 보장하기에 부족하다. 이에 본 논문에서는 기존 마이데이터 플랫폼의 한계점을 분석하고, Web3.0 등 변화하는 환경에서 개인의 데이터 주권을 보장하고, 데이터 가치를 공정하게 분배받을 수 있는 DID 플랫폼 기반의 마이데이터 서비스 모델을 제안한다.

A Proposal on the Service Usage Context information based Extended Security Policy Framework in BYOD, Telework Environment (BYOD, 스마트워크 환경에서 확장된 이용 상황정보 기반 보안 정책 구조 제안)

  • Park, Hyun-Seung;Kang, Dong-Wan;Im, Chae-Tae
    • Proceedings of the Korean Society of Computer Information Conference
    • /
    • 2014.07a
    • /
    • pp.375-378
    • /
    • 2014
  • 예전 기업 그룹웨어 환경은 기업 소유의 기기을 활용하는 사내에 출근한 직원들 대상으로만 서비스 하였다. 그러나, 스마트폰 보급이 확대되면서 사외에서 기업내부로 접근하여 그룹웨어 등을 활용할 수 있는 스마트워크 서비스가 발전하였다. 또한 사내로 반입된 개인 소유 단말 기기가 그룹웨어 서비스를 접속할 수 있는 BYOD 도입 기업들이 증가하고 있다. BYOD, 스마트워크 환경에서 기기 접속 위치, 시간 등 다양한 접속 상황을 활용한 보안정책 관리 구조를 연구하였다. 본 논문에서는 서비스 접속 이후 보안에 취약한 서비스 접근 상황정보 중심 보안정책의 한계를 개선하기 위하여 서비스 웹/DB 서비스 이용 상황정보 기반 보안정책 구조를 제안한다.

  • PDF

A Research on Extension Device of Korea Private Security Market (한국 민간경비 시장의 과제와 활성화 도입방안)

  • Park, Jun-Seok
    • Korean Security Journal
    • /
    • no.15
    • /
    • pp.173-198
    • /
    • 2008
  • As we took a look at above, this researcher suggest following device to extend Korea's private security industry's area. First, it is necessary to extend private investigation law's area grafting private security together. Second, it is necessary it is necessary to think of private security's role related key figure law, corresponding terror law, Presidential Security Service Guard law. Third, as a draft of a proposed law related prevention flowing out of industry techniques among industry security related law, passed, it is necessary private security's diversity, subdivision, composition through an enterprise security, and private security industry area's grafting together. Fourth, a research about private security company's investment and professional area's bringing up as well as business's extension device should be groped for the security consulting though total system management service. Fifth, there are no big difference education course and purpose, duty about a security police man law and security law's unification, so it is necessary to drive forward actively unification through government organization's cooperation. Sixth, a paradigm shift should be occured about private security service among policeman, citizen, and private security guards. Seventh, it is considered the role of security association is important. Lastly about a matter communication between the National Police Agency, and Security Association, not only look at from an authority's angle, collecting information, corresponding ability but now it is considered to grope each other cooperation device together among organizations not only the National Police Agency but also, National Organization, National Intelligence Service, the prosecution, Presidential Security Service Guard, Army etc.

  • PDF

A Critical Review of the Transfer of Presidential Security Work to the Police (대통령경호업무 경찰 이관에 대한 비판적 소고)

  • Jo, Sung-gu
    • Korean Security Journal
    • /
    • no.58
    • /
    • pp.177-194
    • /
    • 2019
  • Last year, the Moon Jae-In administration made an attempt to abolish the presidential security office overseeing the presidential security and to transfer the work to the presidential security service under the National Police Agency. Currently, all of the G7 nations maintain a security system spearheaded by the police, so the policy of transferring the presidential security to the National Police Agency may be discussed. However, it is necessary to focus on the following reality. First, the current presidential security system is consisted of the overlapping security organizations classified into (1) inner ring of the presidential security agency, (2) middle ring of the police agency, and (3) outer ring of the capital defense command. If the presidential security agency is abolished, a vacuum will result as per the principle of class. Second, for the efficient security guard of the President, currently, the presidential security agency at the Presidential Security Safety Measure Committee plays the role of coordinating the tasks. If the National Police Agency becomes the control tower of the presidential security, whether command will be available for the military and diplomatic aspects of the presidential security work should also be considered. Third, Korea is currently in a truce with North Korea, so there is a big difference in terms of the security environment with such G7 nations as the UK, Germany, France, and Japan.

Light-weight Defense Mechanisms for application layer DDoS Attacks in the Web Services (웹서비스 대상 경량화 된 응용계층 DDoS 공격 대응 메커니즘)

  • Lee, Tai-Jin;Im, Chae-Su;Im, Chae-Tae;Jung, Hyun-Chul
    • Journal of the Korea Institute of Information Security & Cryptology
    • /
    • v.20 no.5
    • /
    • pp.99-110
    • /
    • 2010
  • Recently, network based DDoS attacks have been changed into application layer DDoS attacks which are targeted at the web services. Specially, an attacker makes zombie PCs generate small traffic and its traffic pattern has been similar to the normal user's pattern. So, existing HTTP PPS based Threshold cannot defend the DDoS attacks effectively. In this paper, we displayed all the GET Flooding attack types and propose three DDoS attack defense mechanisms which are simple and very powerful. Proposed mechanisms can defend all the existing GET Flooding DDoS attacks and be deployed in the real environment immediately with little resource consumption.

Study of Information Security Pre-Evaluation Model for New IT Service (신규 IT서비스에 대한 정보보호사전평가모델 연구)

  • Shin, Dong-Hoon;Kim, Sung-Hoon;Lee, Kang-Shin
    • Proceedings of the Korea Information Processing Society Conference
    • /
    • 2005.11a
    • /
    • pp.991-994
    • /
    • 2005
  • 통신기술의 급속한 발전으로 네트워크 환경이 광대역통합망으로 진화되어가고 있다. 이로 인해 개별 네트워크에서 운영되던 IT서비스들 또한 광대역통합망 환경에서 빠른 속도로 융합되고 있다. 하지만, 개별 네트워크에서 운영되던 기존의 IT서비스들이 광대역통합망에서 서로 융합되어 신규 IT 서비스를 생성하는 과정에서 보안요소가 적용되지 않을 경우에 신규 IT서비스의 안정성 및 신뢰성이 떨어질 수 있다. 이러한 문제점을 해결하기 위해서, 본 논문에서는 신규 IT 서비스의 기반구축 및 운영이전인 서비스에 대한 기획 및 설계시에 필수적인 보안대책 제시하여 서비스 운영이전에 보안대책을 적용할 수 있도록 함으로써, 신규 IT 서비스의 안정성과 신뢰성을 확보할 수 있는 방법으로 정보보호사전평가 모델을 설명한다.

  • PDF

Analysis and Classification of Security Threats based on the Internet Banking Service (인터넷 뱅킹 서비스에서의 보안위협 분류 및 분석)

  • Lee, Kyung-Roul;Lee, Sun-Young;Yim, Kang-Bin
    • Informatization Policy
    • /
    • v.24 no.2
    • /
    • pp.20-42
    • /
    • 2017
  • In this paper, we focus on classification of security threats and definitions of security requirements for Internet banking service. Threats are classified based on the past and potential incidents, based upon which we will be able to propose security requirements. In order to identify security threats, the structure of the Internet banking service is classified into three sections - the financial institutions, the network, and the user-terminal - and we defined arising threats for each section. We focused the analysis especially on the user-terminal section, which is relatively vulnerable, causing difficulties in securing stability of the service as a whole. The analyzed security threats are expected to serve the foundation for safe configuration of various Internet banking services.

A Proposal for amendment of the Financial Intelligence Unit Law (『특정금융정보(FIU)법』의 개정을 위한 제언)

  • Lee, Dae Sung;Ahn, Young Kyu
    • Convergence Security Journal
    • /
    • v.15 no.5
    • /
    • pp.71-76
    • /
    • 2015
  • Financial Intelligence Unit Law doesn't include investigation on important cases that could influence the security and existence of the nation that are the core jobs of national intelligence agency. So the agency has a difficulty to investigate the international crime of North Korea and other security incidents. It is also difficult to catch an international crime organization working in Korea. It also produces problems such as difficulty in investigating the illegal leak of strategic materials and investigating people related to illegal funding to international terrorism. So it is urgently needed to revise Financial Intelligence Law as soon as possible. Foreign intelligence agencies use the information of financial intelligence unit in many different ways. National Security Agency of China and Australian Security Intelligence Organization freely use the information of financial intelligence unit based on their own laws and systems. Central Intelligence Agency and Federal Bureau of Investigation of USA and Secret Intelligence Service and Security Service of Britain request financial intelligence units to supply them with the information of financial intelligence unit. But the national intelligence agency of Korea isn't able to approach to FIU and can't share the FIU information with foreign intelligence agencies. To solve the problem, they should revise Financial Intelligence Unit Law so that national intelligence agency can receive or request information from Korean Financial Intelligence Unit.

지상 최대의 화두, DDoS 공격을 막아라

  • Korea Information Security Agency
    • 정보보호뉴스
    • /
    • s.126
    • /
    • pp.12-16
    • /
    • 2008
  • DDoS(Distributed Denial of Service) 공격이 정보보호 분야의 최대 뉴스 메이커로 떠올랐다. 실제로, 지난 3월 13일 민간 기업 및 기관 정보보호 담당자들이 모인 2008년 한해 정보보호 이슈를 전망해 보는 'CONCERT FORECAST 2008-기업 정보보호 이슈 전망'에서 기업 정보보호 담당자들은 DDoS 공격을 최대 이슈로 꼽는데 주저하지 않을 만큼 DDoS 공격은 더 이상 '남의 집 불구경'이 아닌 것이 돼 버렸다. 하지만 공론화되는 DDoS에 대한 이슈만큼이나 정보보호 관계자들을 답답하게 하는 것은 DDoS 공격에 대해 아직까지 국내는 물론, 해외에서 조차 속 시원한 해법을 내놓는 전문가가 없다는 점이다. 이번 호에서는 DDoS 공격에 대해 기업, ISP, IDC 등에서 마련하고 있는 DDoS 대응현황을 살펴보고자 한다.

  • PDF